Closed Bug 1514231 Opened 5 years ago Closed 5 years ago

[wpt-sync] Sync PR 14522 - SignedExchange: Require nosniff in outer response headers

Categories

(Testing :: web-platform-tests, enhancement, P4)

enhancement

Tracking

(firefox67 fixed)

RESOLVED FIXED
mozilla67
Tracking Status
firefox67 --- fixed

People

(Reporter: mozilla.org, Unassigned)

References

()

Details

(Whiteboard: [wptsync downstream])

Sync web-platform-tests PR 14522 into mozilla-central (this bug is closed when the sync is complete).

PR: https://github.com/web-platform-tests/wpt/pull/14522
Details from upstream follow.

Kouhei Ueno <kouhei@chromium.org> wrote:
>  SignedExchange: Require nosniff in outer response headers
>  
>  To encourage servers to include the nosniff header, this CL makes
>  Chromium reject SXG served without the "X-Content-Type-Options: nosniff"
>  header.
>  
>  Bug: https://github.com/WICG/webpackage/pull/348
>  Change-Id: I5343a8d13a42a3c9144f05d871777d35a20a77b7
>  Reviewed-on: https://chromium-review.googlesource.com/1373430
>  WPT-Export-Revision: 129b2c6a9bbc2c9134a7496527f7cb1582d48eea
PR 14522 applied with additional changes from upstream: 2e19cbe5d5d74821056d4ae2cef435accefaf4ef
Pushed by james@hoppipolla.co.uk:
https://hg.mozilla.org/integration/mozilla-inbound/rev/8e0c10dc5825
[wpt PR 14522] - SignedExchange: Require nosniff in outer response headers, a=testonly
Pushed by james@hoppipolla.co.uk:
https://hg.mozilla.org/integration/mozilla-inbound/rev/768b0b422609
[wpt PR 14522] - SignedExchange: Require nosniff in outer response headers, a=testonly
Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla67
You need to log in before you can comment on or make changes to this bug.